Compliance
Evidence for the frameworks you answer to
PRISM records what your AI did and why. When an auditor, regulator, or customer asks, you map that evidence to their framework instead of rebuilding history from logs.
How it works
From daily evidence to a report someone can sign
Every plan produces the evidence. The report is a service you request.
- 01RecordTraces, sessions, evaluations, and guardrail events accumulate as your AI runs. This happens on every plan, from day one.
- 02MapCompliance Reports map that stored evidence to the controls of a supported framework. This is a service, delivered on request — you name the framework, and the scope is agreed before work starts.
- 03Review and shipA person reviews the mapped evidence, resolves the gaps, and attests. The report goes out reviewed, not generated and forgotten.
Compliance reporting is not part of any self-serve plan — it is requested, scoped, and delivered as a service. A set of frameworks is supported today, including the most requested US and EU frameworks. New frameworks are added through sponsored development: the first customer who needs one funds it, and everyone after benefits.
Frameworks
Twelve frameworks, one evidence layer
What each framework asks for, and the PRISM evidence that answers it.
EU AI Act
Risk classification, logging, and human oversight duties for AI systems in the EU. PRISM evidence shows what the system did and who approved each change.
See the framework page →NIST AI RMF
The govern, map, measure, manage cycle. Traces, evaluations, and reviews become the measure and manage record.
See the framework page →ISO/IEC 42001
The auditable AI management system standard. Operational evidence for the clauses an internal auditor asks to see.
See the framework page →SR 11-7 model risk
Model risk management discipline applied to AI and LLMs. Monitoring, validation, and change history in one place.
See the framework page →NY DFS Part 500
Cybersecurity oversight extended to AI systems, with incident evidence and access records examiners expect.
See the framework page →NAIC Model Bulletin
AI governance for insurers: documented testing, decision oversight, and incident handling with evidence attached.
See the framework page →CFPB and Reg B
Adverse decisions need explanations. Session-level evidence of what the model saw, did, and decided.
See the framework page →HIPAA
PHI inside AI workflows. Redaction activity and access records that support the Privacy and Security Rules.
See the framework page →GDPR
Lawful processing and data minimization for AI. Evidence of what was collected, kept, and deleted.
See the framework page →DORA
ICT risk and incident reporting for EU financial entities, with AI systems part of the operational record.
See the framework page →SOX
AI touching financial reporting needs documented controls and change management. Versioned, reviewable evidence.
See the framework page →PCI DSS
Cardholder data kept out of AI logs. Guardrail events and redaction evidence on the paths that matter.
See the framework page →
The boundary
Evidence, not certification
PRISM supports evidence and reporting. Legal interpretation, formal certification, and regulatory sign-off stay with your organization and qualified advisers. We also keep a deliberate separation: helping you fix a system and independently certifying that system are different jobs, and we do not blur them.
Questions
Asked before every review
Does this certify us?
No. PRISM produces the operational evidence and reporting that audits, reviews, and certifications rely on. The certification itself, and the legal interpretation behind it, stay with your organization and its advisers.
Which plan includes Compliance Reports?
None — compliance reporting is not part of any plan. Compliance Reports, framework mappings, and Trust Packs are delivered as a service, on request, with the scope agreed before work starts. Every plan records the underlying evidence from day one, so nothing is lost while you decide.
Can we start before an audit is on the calendar?
Yes, and that is the cheapest time. Connect the app, let evidence accumulate as you operate, and the eventual report draws on months of history instead of a scramble the week before.
Ask us about your framework
Tell us who you answer to and we will show you the evidence path.